Skip to content

test(coverage): ratchet the unit region floors to the 100% scripts/ and src/ already measure - #1298

Merged
mrbobbytables merged 3 commits into
mainfrom
quality/test-ratchet-unit-coverage-floors
Oct 11, 2026
Merged

mrbobbytables merged 3 commits into
mainfrom
quality/test-ratchet-unit-coverage-floors

Conversation

@hivecommons-hive

@hivecommons-hive hivecommons-hive Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

Test Improvement

npm run test:unit:coverage:check is the gate the required "Validate
repository" check runs. Three of its eight floors sat below what the suite
already achieves:

flag was now measured
--check-regions 95 96 96.12
--check-source-regions 99 100 100.00
--check-source-file-regions 97 100 100.00 (lowest single file)

scripts/ and src/ are at 2753/2753 regions — every region executed, and
every file in both trees at 100.00% on its own — while the gate asked for 99%
in aggregate. 27 source regions could go uncovered before a single run turned
red
, and the per-file floor let any one file give up 3% of its own on top of
that.

tests/coverage-gate-thresholds.test.mjs states the rule this breaks in its own
header — "When coverage climbs and the package.json thresholds are ratcheted up
with it, raise these floors in the same change."
The climb happened and the
ratchet did not: its recorded measurement was stale by 278 regions
(2475/2476 against 2753/2753 today).

Unlike the browser gate, which deliberately sits under its ceiling because 18
regions are uncreditable (#1256, #1236), the unit source number has no
residual list to leave room for. It is a true 2753/2753, so 100 is the measured
floor rather than an aspirational one.

Files

  • package.json — the three threshold values on test:unit:coverage:check.
  • tests/coverage-gate-thresholds.test.mjs — the matching FLOORS entries,
    plus the stale measured-numbers comment above them refreshed, and the reason
    each new floor is where it is.
  • CONTRIBUTING.md, AGENTS.md — both restate these thresholds in prose and
    are gated by tests/docs-threshold-parity.test.mjs, which fails if they drift
    from package.json. They move in the same commit by that test's design.

Verification

  • npm run test:unit:coverage:check on node v22.21.1 — the major ci.yml
    pins via node-version: 22 — exits 0: # pass 2317, # fail 0.
  • The same coverage measurement was taken on node v26.10.0 as well, because
    region counts are a V8 artifact and a floor at exactly 100 is only safe once
    it has been shown not to move with the runtime. The two runs agree to the
    region: src files 100.00 | 100.00 | 9135/9135 lines | 2753/2753 regions.
  • The floors genuinely bite rather than being parsed and discarded: the same
    reporter run with --check-harness-file-regions 98 exits 1 with
    tests/tools/e2e-coverage-report.mjs 97.98% (485/495 regions ...).
  • npx prettier --check, markdownlint and cspell are clean on all four
    files.

Rebased 2026-10-11 (after #1294 and #1305 merged)

The figures above are from 4184f33. On current main the ratcheted floors
still clear, and the recorded measurements in
tests/coverage-gate-thresholds.test.mjs were refreshed to the new tree:
src files 100.00 | 100.00 | 9233/9233 lines | 2777/2777 regions;
harness files 100.00 | 99.57 | 5336/5336 lines | 1867/1875 regions (now
including tests/helpers*.mjs, lowest file helpers-script-sandbox.mjs at
97.06); all files 99.65 | 96.14. e2e-coverage-report.mjs sits at its new
98.57% ceiling (7 residual regions after #1305). Full
npm run test:unit:coverage:check is green on the rebased branch.

This PR also folds #1306: AGENTS.md:54 and CONTRIBUTING.md:182 said the
per-file harness floor was 93%, stale since #1250; both now say 97%.

Deliberately out of scope

The two --check-harness-* floors are left at 97 against a measured 99.32.
#1294 rescopes harness scoring to take in tests/helpers*.mjs, whose lowest
file is 97.06%, which moves both harness numbers; ratcheting them here would
collide with that PR. They should be ratcheted in its wake. This PR touches no
file #1294, #1289, #1293 or #1296 touches.

Related Issue

Closes #1297
Closes #1306 (the stale "93% regions per harness file" in AGENTS.md:54 and CONTRIBUTING.md:182 sits on lines this PR already edits; corrected to 97 here)


Filed by quality agent (hold-gated mode). Human review required.

— hive: agent=quality backend=copilot model=claude-opus-5 copilot=1.0.88

@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "quality" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will keep the hold label until a human removes it. Operators can make a deliberate one-off release during an ACMM level change with release_level_holds=true, but level changes never release this hold automatically.

@hivecommons-hive

Copy link
Copy Markdown
Contributor Author
0afda0b

ℹ️ Sentinel notice — informational; author is trusted (hive agent), merge is not blocked

Hive flagged this PR (author @hivecommons-hive[bot], head 0afda0b8d13f) because it matches behaviors that can override security controls, escalate privileges or damage the codebase. This is a heuristic, not an accusation — a maintainer should confirm the change is intended before it merges.

  • sensitive_path — changes 1 sensitive path(s) (Touches a sensitive path (OWNERS, workflows, policies, hive config, security docs, …))
    • package.json

Hive did not add the sentinel-alert label because this author is trusted. The finding remains recorded for audit and the dashboard Security tab; set sentinel.trusted_authors_block: true to require the blocking label for trusted authors too.

mrbobbytables added a commit that referenced this pull request Oct 11, 2026
…a array

The `entry.via ?? []` fallback in reportedAdvisoryIds() had no test reaching
it, leaving scripts/audit-gate.mjs at 98.04% regions, the one source file
under 100% and the one that would fail the ratchet in #1298.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Bob Killen <bkillen@linuxfoundation.org>
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author
be47744

ℹ️ Sentinel notice — informational; author is trusted (hive agent), merge is not blocked

Hive flagged this PR (author @hivecommons-hive[bot], head be47744ca070) because it matches behaviors that can override security controls, escalate privileges or damage the codebase. This is a heuristic, not an accusation — a maintainer should confirm the change is intended before it merges.

  • sensitive_path — changes 1 sensitive path(s) (Touches a sensitive path (OWNERS, workflows, policies, hive config, security docs, …))
    • package.json

Hive did not add the sentinel-alert label because this author is trusted. The finding remains recorded for audit and the dashboard Security tab; set sentinel.trusted_authors_block: true to require the blocking label for trusted authors too.

quality and others added 3 commits October 11, 2026 09:18
…nd src/ already measure

`test:unit:coverage:check` is the gate ci.yml runs, and three of its eight
floors sat below what the suite achieves. scripts/ and src/ are at 2753/2753
regions -- every region executed, every file in both trees at 100.00% on its
own -- while the gate asked for 99% in aggregate and 97% per file, so 27 source
regions could go dark before a run turned red.

tests/coverage-gate-thresholds.test.mjs states the rule this breaks in its own
header: raise these floors in the same change when coverage climbs. The climb
happened and the ratchet did not; its recorded measurement was stale by 278
regions (2475/2476 against 2753/2753 today).

  --check-regions             95 -> 96   (measured 96.12)
  --check-source-regions      99 -> 100  (measured 100.00)
  --check-source-file-regions 97 -> 100  (lowest source file 100.00)

Unlike the browser gate, which stays under its ceiling because 18 regions are
uncreditable (#1256), the unit source number has no residual list, so 100 is
the measured floor rather than an aspiration. Measured twice -- node v22.21.1,
the major ci.yml pins, and node v26.10.0 -- because region counts are a V8
artifact and a floor at exactly 100 is only safe if it does not move with the
runtime. The two runs agree to the region.

The two --check-harness-* floors are deliberately left at 97: #1294 rescopes
harness scoring to take in tests/helpers*.mjs, whose lowest file is 97.06%, and
ratcheting them before that lands would collide with it.

CONTRIBUTING.md and AGENTS.md restate these thresholds in prose and are
gated by tests/docs-threshold-parity.test.mjs, so they move in this commit too.

Closes #1297

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: quality <quality@hive.kubestellar.io>
…ONTRIBUTING.md

Both files still said 93%, stale since #1250 ratcheted
--check-harness-file-regions to 97. They are the lines this change already
edits, so the fix rides here.

Closes #1306

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Bob Killen <bkillen@linuxfoundation.org>
Rebased onto main: src is 2777/2777 regions, the harness row now includes
tests/helpers*.mjs (5336/5336 lines, 1867/1875 regions, lowest file
helpers-script-sandbox.mjs at 97.06), and e2e-coverage-report.mjs's ceiling
is 98.57 with 7 residual regions. All three ratcheted floors still clear.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Bob Killen <bkillen@linuxfoundation.org>
@mrbobbytables
mrbobbytables force-pushed the quality/test-ratchet-unit-coverage-floors branch from be47744 to b37ce6e Compare October 11, 2026 14:19
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author
b37ce6e

ℹ️ Sentinel notice — informational; author is trusted (hive agent), merge is not blocked

Hive flagged this PR (author @hivecommons-hive[bot], head b37ce6efb236) because it matches behaviors that can override security controls, escalate privileges or damage the codebase. This is a heuristic, not an accusation — a maintainer should confirm the change is intended before it merges.

  • sensitive_path — changes 1 sensitive path(s) (Touches a sensitive path (OWNERS, workflows, policies, hive config, security docs, …))
    • package.json

Hive did not add the sentinel-alert label because this author is trusted. The finding remains recorded for audit and the dashboard Security tab; set sentinel.trusted_authors_block: true to require the blocking label for trusted authors too.

@mrbobbytables
mrbobbytables added this pull request to the merge queue Oct 11, 2026
Merged via the queue into main with commit cc447d8 Oct 11, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

1 participant